overleaf/services/web/app
Simon Detheridge 56dcbefb5b Check for safe paths in all ProjectEntityHandler methods
Some import mechanisms (for example, Github project import) call methods such as 'upsert*' directly, bypassing existing filename checks.

Added checks to all methods in ProjectEntityHandler that can create or rename a file.

bug: overleaf/sharelatex#908
Signed-off-by: Simon Detheridge <s@sd.ai>
2018-10-08 15:31:04 +01:00
..
coffee Check for safe paths in all ProjectEntityHandler methods 2018-10-08 15:31:04 +01:00
templates/project_files Fix typo and file extension in example tex template 2018-02-06 10:27:10 +00:00
views Merge pull request #926 from sharelatex/dcl-i850 2018-10-08 13:59:04 +01:00